Back to Discover

agent-action-gate

connector

AAH20

Gate/Prove: deny unattended destructive agent tools. Instant Audit $499 on a2zsoc.com.

View on GitHub
0 starsSynced Aug 17, 2026

Install to Claude Code

/plugin marketplace add AAH20/agent-action-gate

README

Agent Action Gate

Gate/Prove runtime for agent and MCP tool calls.

Normalize tool intent → deny unknown → never treat model confidence as approval → HITL prove on destructive / provision / decommission → Action Ledger (hash chain).

Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.

Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.

Why this exists (revenue + cost)

AI-agent companies do not pay for “another MCP.” They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.

Cost driverWhat this gate doesBuyer outcome
Ungated shell.exec / disable-control / decommissionDENY unless HITL prove token + approvedAvoid production blast
Agent “95% sure”never_equate_intent_to_approval: trueIntent ≠ ledger proof
Write tools fire on first thoughtDefault SIMULATE (no side effects)FDE minutes, not incident cost
No audit trailAppend-only Action Ledger with hash chainDiligence packet

Hard rule: never equate agent intent or model score to human approval.

Illustrative cost sketch (not a quote): make bench.

Quick start

make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench

Unattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.

export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"

Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.

MCP stdio server

This process never executes tools. Clients call gate_check before they would invoke a destructive tool.

PYTHONPATH=. python3 -m aag serve

Cursor / Claude example (mcpServers):

{
  "agent-action-gate": {
    "command": "python3",
    "args": ["-m", "aag", "serve"],
    "cwd": "/path/to/agent-action-gate",
    "env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
  }
}

Docker / registry image:

docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0

Official MCP Registry name: io.github.AAH20/agent-action-gate

Envelope

Every decision includes:

  • never_equate_intent_to_approval: true
  • allow_auto_execute (false on unattended high tiers)
  • mode: deny | simulate | allow
  • ledger_id / receipt_hash
  • CTAs: Instant Audit + consultation

Library mapper

Same Gate/Prove policy from Python without the stdio loop:

from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call

gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})

Fixtures (labeled, not payloads)

FileTechniqueExpected
t1059_unattended_shell.jsonT1059DENY unattended destructive
t1078_read_identity.jsonT1078ALLOW read
t1562_impair_defenses.jsonT1562DENY unattended destructive
write_ticket_simulate.jsonSIMULATE write
proved_decommission.jsonT1578ALLOW only with HITL token

Layout

aag/
  gate.py      HITL + kill-switch + unknown deny
  ledger.py    hash-chained JSONL
  server.py    MCP stdio (gate_check, ledger_verify)
  mcp.py       MCP tools/call mapper (no execution)
  cost.py      illustrative avoidance sketch
  demo.py      fixture runner
fixtures/      ATT&CK-tagged cases
server.json    MCP Registry metadata
tests/         Gate/Prove + MCP contract

Paid evaluation (not free prove)

If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:

$499 Instant Audit
consultation (sprint / vCISO)

Unpaid take-homes: refuse — run make demo and buy Instant Audit.

License

MIT

Rendered live from AAH20/agent-action-gate's GitHub README — not stored, always reflects the source repo.

1 Install Method

NameDescriptionCategorySource
mcpb packageInstall via mcpb (stdio transport)mcp-serverhttps://github.com/AAH20/agent-action-gate/releases/download/v0.2.0/agent-action-gate.mcpb

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.